
"AI is not a thing here." We hear this sentence in first conversations more often than you would expect, and it is almost never true.
Not a thing means, in practice: not an official thing. In marketing, someone has long been drafting customer emails with ChatGPT. In sales, someone summarizes long proposals with a free tool. And the executive assistant has meeting minutes transcribed by an AI whose name nobody in the building knows. All of this runs through private accounts, often on private devices, and it has never been mentioned in any meeting. That is exactly what shadow AI is.
The reflex, once management notices, is reliably the same: ban it. Block access, send out a directive, case closed. In our experience, that is the moment a solvable problem turns into an invisible one.
What is shadow AI?
Shadow AI is the use of AI tools by employees without the company's knowledge or approval: private ChatGPT accounts, free tools from the browser, AI features inside software already in use. The term borrows from shadow IT. The difference: with shadow AI, business data frequently flows into systems the company controls neither contractually nor technically.
And the phenomenon is broader than the obvious chatbots suggest. AI now sits inside translation services, note-taking apps, meeting assistants and browser extensions. The meeting bot that shows up uninvited in a video call because one participant subscribed to it privately is just as much shadow AI as the ChatGPT window in the second tab. Part of your shadow AI was never consciously introduced. It arrived as a feature update in a tool that was already there, or as a guest in a meeting nobody invited it to.
Important for perspective: this is the normal case, not the exception. We have yet to see a company where the AI usage on the ground matched the officially known one. The question is not whether shadow AI exists in your company. The question is how large the gap between assumption and reality is.
Why your people reach for shadow AI
The story behind shadow AI is less spectacular than the name sounds.
Nobody on your team gets up in the morning to undermine the company's data security. There is someone who has to finish a report by 4:30 pm and knows a language model saves them an hour. There is someone writing the same proposal text for the third time and thinking: a machine can do this too. Shadow AI emerges where the benefit is obvious and the official path is missing.
This is exactly the same mechanic that brought Dropbox and private WhatsApp groups into companies years ago. People are faster than the organization. Uncomfortable, yes. But it also carries the message that usually gets lost in the heated discussions: you no longer have to convince anyone of AI. Your team is already testing it, on its own initiative and partly at its own expense. Shadow AI is the most honest demand signal you will ever get. It shows you precisely which processes are too slow and which tools are too weak.
A pattern we see often: shadow AI is used most intensively where repetitive text work meets deadline pressure. Proposals, reports, translations, minutes. These are rarely the departments a management team thinks of first when AI comes up. Whoever only looks at IT is searching in the wrong place. In our experience, the most productive and at the same time least controlled usage sits in the back office, in sales and in administration, with people who want to get their work done faster.
Whoever reads shadow AI only as a security hole misses half the information.
What a ban achieves
A ban feels like control. As a rule, it achieves three things, and none of them is control.
First, the usage does not disappear, it migrates. From the company laptop to the private phone, from the known tool to an unknown one. On the private free account, the provider's consumer terms apply: depending on account and settings, inputs may be used to improve the models, there is no data processing agreement with your company, no logs, no way to delete data centrally. The common business versions rule out exactly that by contract. A ban therefore pushes your business data from the better contractual position into the worse one.
Second, you lose the information. Who asks whether a new tool is acceptable when the answer is certain to be no? After the ban, nobody tells you what they use anymore. Your picture of the situation does not get better, it gets darker.
Third, the ban changes nothing about your responsibility. The company remains responsible for the processing of personal data, and that processing has to be compliant with the Swiss data protection act even if it ran through a private account nobody officially knew about. And whoever waits for a Swiss AI law to bring clarity is waiting for the wrong event: the Federal Council decided in February 2025 not to enact a dedicated AI law for now. The data protection act, however, has applied all along, including to every AI input containing personal data.
To be fair: there is one place where a clear no is right. It just concerns data categories, not tools. Sensitive personal data, client secrets or numbers before a deal closes have no business in any unapproved tool, no matter how good it is. A no to specific data can be explained and enforced. A no to an entire technology that sits in every browser can only be asserted.
For reassurance, because this topic gets dramatized: none of this is an emergency. It is a task list. And it is shorter than you think.
Make it visible instead of hunting it: the three steps
The path that works in our mandates is unspectacular and requires no new security product.
Step 1: an inventory by asking, not by scanning. Discovery tools that detect AI usage on the network exist, and in large environments they have their place. In an SME, the more direct route is usually the better one: ask your team, openly and without threat of sanctions. Which tools do you use, for what, with which data? For that to produce honest answers, one simple promise is needed: this is about order, not blame. Whoever opens the round with a written warning in mind gets an empty list and keeps the problem. The list that emerges from an honest round is valuable twice over. It is your AI inventory, and it is a process map of your bottlenecks.
Something sober then happens with this list: triage. In our experience, the largest share of entries lands in the "approve" bucket, often with the condition of switching to the company account. A second share gets consolidated because three tools do the same job. And only a small remainder belongs in the "stop" bucket, almost always because of the data category, not because of the tool. If everything ends up in the stop bucket at the end of your inventory, it was not an inventory, it was a ban with a detour.
Step 2: offer an official channel. The most effective protection against the workaround is a convenient main road. Concretely: a company account with a provider, with a contract, central administration and the assurance that inputs do not flow into training. From that moment, the logic flips. Before, the private account was the fastest path; now it is the more cumbersome one. Which data may then go into which tool is what we described with a simple list system in Which company data is allowed in ChatGPT?
Step 3: get the rules onto one page. No 20-page directive nobody reads. One page: which data categories may go into approved tools, which may not, and who decides on new tools. The last point is the most important one, because new AI tools appear weekly, and your rule has to withstand that future without being rewritten every time. One named person, a short review path, an answer within days instead of months. Why one page is enough and what it looks like is covered in Do we need an AI policy?
A side effect that gets overlooked in budget conversations: the inventory step regularly washes paid individual subscriptions to the surface, running through expense reports. Three people with three individual subscriptions for the same job, that is the license sprawl of shadow IT in a new form. Whoever consolidates the channel cleans up the costs along the way.
If you want to approach this in a structured way, embedded in your existing security setup instead of as an island project, that is the core of our AI governance work.
The sentence that gives it away
Back to the beginning. "AI is not a thing here" is not reassurance, it is a measurement error. The sentence does not describe the usage in your company, only your view of it. The usage itself has long been running; the only open question is whether it runs through accounts you have under control or through ones you know nothing about.
The good news stands: the distance between those two states is not a major program but three sober steps. Ask, channel, one page of rules. Most of it you can get done in weeks, not quarters.
If you want an outside view from someone who has seen a few of these inventories: an initial conversation costs nothing and commits you to nothing.
And if you want to know beforehand: if you ask your team tomorrow which AI tools are in use, how many do you think will come together?




